matousec.com (site map)

Poll

Your favourite antivirus families?

  Comodo (31.59%)

  NOD32 (Eset) (21%)

  Kaspersky (17.73%)

  AntiVir (Avira) (16.71%)

  avast! (13.39%)

  Symantec (4.16%)

  AVG (3.79%)

  Dr.Web (3.43%)

more

results

Advisory 2007-01-01.01

Kerio Fake 'iphlpapi' DLL injection Vulnerability

Basic information:


Release date: January 01, 2007

Last update: March 12, 2007

Severity:Critical

Character:Complete system control

Status:Unknown

Testing program: BTP00002P001SK.zip

Description:

When Sunbelt Kerio Personal Firewall (SKPF) loads dependant modules, it relies on the operating system. System library iphlpapi.dll is located in the system directory but the main SKPF service, which requires and loads this DLL, is located in the installation directory of SKPF. This is why it tries to find iphlpapi.dll in its installation directory at first and then, if it is not found in this directory, it tries to find it in the system directory. Moreover, it is possible to create new files in the installation directory of SKPF. A malicious application can create a fake iphlpapi.dll in the installation directory of SKPF, which will be loaded by the operating system into the SKPF service during its initialization. This is how the malicious application is able to execute an arbitrary code inside SKPF service and bypass any of its security mechanisms.

Vulnerable software:

Events:

References: